Skip to content
folhas.io
secure by design for connected products

Secure by design for the people who make connected products.

The Cyber Resilience Act makes the manufacturer responsible for a product's security across its whole life cycle, not just at the moment it leaves the factory. Treating that as an engineering problem rather than a paperwork problem is what makes the difference.

Independent, Portuguese and technical consultancy for small and medium manufacturers of connected hardware and of software sold as a product.

The CRA guide for manufacturersWhat we do

You make a connected product and want to know where it stands under the CRA? Ask for a first read, at no cost

CRA calendar

2024-12CRA in force
2026-07Commission guidance
2026-0924h / 72h reporting
2027-12Full application
today

456 daysuntil Full application for manufacturers (11 Dec 2027)

  1. 10 Dec 2024The Cyber Resilience Act enters into force. Manufacturer obligations only become applicable later, in phases. Regulation (EU) 2024/2847
  2. 27 Jul 2026The European Commission publishes practical guidance on applying the CRA. European Commission
  3. 11 Sep 2026The reporting obligations become applicable: an early warning within 24 hours and a notification within 72 hours for actively exploited vulnerabilities and severe incidents. Regulation (EU) 2024/2847, Article 14
  4. 11 Dec 2027The CRA becomes fully applicable. From here on, products with digital elements placed on the market must meet the essential cybersecurity requirements. Regulation (EU) 2024/2847

Where we come from

We come from offensive security: pentesting, red teaming, OffSec certifications. That is the angle we bring to a product. We follow the path an attacker would take, instead of working down a list of requirements to tick off. In a market where the CRA is sold as an audit, the difference shows in the report.

The automotive sector has already been through this transition, with UNECE R155/R156 and ISO/SAE 21434. In practice, those standards are a secure development life cycle applied to a connected physical product. Vehicles are excluded from the CRA precisely because they already have a regime of their own, which is why they preview what is coming for everyone else.

SectorRegime they face
Automotive
German car manufacturer
UNECE R155/R156 · ISO/SAE 21434
Telecommunications
Tier-1 operator
NIS2 · DL 125/2025
Banking
Portuguese retail bank
DORA
Fintech
B2B payments
DORA
Integration
International consultancy (partnership)
Varies with the end client

Clients identified by generic descriptor. Scopes of work, findings and architectures are never published.

And from the maker's side of the table

We are developing our own agricultural IoT product. When it reaches the market, it will be subject to the same regulation we advise on.

That forces us to walk the whole path ourselves: SBOM, support-period decisions, a coordinated vulnerability disclosure process, conformity assessment. The logbook documents that preparation in the open, including any decisions that turn out badly.

A note on rigour. Folhas Etéreas does not yet place products on the market, so no CRA deadline applies to us directly. The dates on this page are the regulation's calendar, not an obligation of ours.

Latest articles

11 Sep 2026

Coordinated vulnerability disclosure: the channel the CRA requires you to keep open

The reporting obligations towards the authorities are now applicable, but they are half of the circuit. Annex I, Part II demands the other half: a public channel for receiving vulnerability reports, with a policy, a point of contact and a process behind it. It costs little to set up, and there is a standard for almost everything.

All articles · RSS